PressedMail
Home
Features
Pricing
Sign InChoose a Pro plan
    • Overview
    • Phishing Reports
    • Links & Images
    • Lock & Impersonation
    • Where Mail Lives
Documentation

Security and Privacy Overview

Understand the PressedMail security model before configuring provider accounts, roles, diagnostics, or AI.

PressedMail's security model has two halves: what the plugin does to protect the mailbox, and what it refuses to do with your data. Both are inspectable. Suspicious content gets a report, and every claim here maps to a control you can open.

A suspicious message, and the report behind the verdict
A suspicious message, and the report behind the verdict

Protecting the mailbox

  • Phishing scanning weighs thirteen classified signals (typosquatting, sender-name mismatch, authentication failure, reply-to mismatch, hidden text and more), and shows the evidence behind the verdict, per message.
  • Link analysis checks a curated lookalike map, shortener and suspicious-TLD heuristics, and link text that disagrees with its destination, without external lookups.
  • Remote images are blocked by default, revealed per message, per user, or disabled site-wide, and loaded through a signed proxy when shown.
  • Rendering is sanitised server-side, with an allowlist of link schemes and a sandboxed iframe under a strict content-security policy.
  • The mailbox lock puts a second passphrase in front of connected mail, granted per browser and revocable across every session at once.
  • Impersonation blocking detects user-switching plugins, so an administrator cannot hop into another user's mailbox.

The privacy boundary: mail and credentials stay on your site and your provider, while only licence checks and any AI action you run leave it.

Two things leave, both on purpose and both visible.

Protecting the data

  • Mail moves directly between your server and your provider; messages are mirrored only into your own WordPress database.
  • Credentials rest under AES-256-GCM with a site-derived key, reachable only inside an explicit guarded context.
  • A connected account is readable only by the WordPress user who connected it, whatever their role.
  • Paid plans retain 365 days of audit history for connection, send, and settings changes, with a pattern guard that refuses to write secrets in the first place.
  • No third-party analytics see message content. Licensing checks reach curb.software; nothing about your mail does.

Free and paid

Sanitised rendering, blocked remote images, impersonation blocking, encrypted credentials, and the mailbox Lock are in every build. The full phishing report, link risk analysis, and 365-day audit log are paid features.

Read Next

  • Security, Sessions, and Audit Protections
  • AI Automation and Security Troubleshooting
Previous

Billing History, Refunds, and Coupons

Find invoices, receipts, refunds, and coupon behavior for PressedMail.

Next

Phishing Detection and Reports

How PressedMail scores a suspicious message, which signals it weighs, and what the safety report actually shows you.

© 2026 PressedMail. All rights reserved.
DocsSupportTermsPrivacyRefunds
PressedMail

A WordPress-Native Email Workspace. Connect your existing email accounts and manage messages, contacts, and calendar from your WordPress dashboard.

Product

  • Features
  • Pricing

Resources

  • Docs
  • Changelog
  • Roadmap

About

  • Contact
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Refund Policy

© 2026 PressedMail. A product of CurbSoftware Tech Innovations.

PressedMail processes email on your WordPress site and connects directly to your email provider. CurbSoftware’s OAuth relay does not receive message bodies or attachments.